CVE Tools

Dovecot

51 CVEs tracked since 2007. Since Apr 2007, none of them reached CISA KEV.

Dovecot CVEs per month

Apr 2007 to Mar 2026. Point at a month, or focus the strip and use the arrow keys.
Dovecot CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2007-0410
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-0810
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-0110
2008-02null or fewer
2008-0320
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-1030
2008-1110
2008-1210
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-0910
2009-10null or fewer
2009-1110
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-0510
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-0910
2010-1040
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-0530
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-0310
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-1210
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-0520
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-0210
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-0320
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-0520
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-0220
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-0830
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-0120
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-0630
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03110

Products

The products that kept showing up in Dovecot's monthly top three, with their CVEs summed over those months.

  1. Dovecot5124 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Dovecot.

  1. CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is l...3.1
  2. CVE-2026-42006An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left ...4.3
  3. CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to d...5.3
  4. CVE-2026-33603Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the...6.8
  5. CVE-2026-27851When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDA...7.4
  6. CVE-2026-27859A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CP...5.3
  7. CVE-2026-27860If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structu...3.7
  8. CVE-2026-27858Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeat...7.5
  9. CVE-2026-27857Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer...4.3
  10. CVE-2026-27856Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential ...7.4
  11. CVE-2026-27855Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP...6.8
  12. CVE-2026-24031Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear aut...7.7
  13. CVE-2026-0394When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the d...5.3
  14. CVE-2025-59032ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access...7.5
  15. CVE-2025-59028When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable se...5.3

The record

Peak rank
#21 in Oct 2010
Busiest month shown
Mar 2026, 11 CVEs
Months with a KEV entry
0 since Apr 2007
Monthly snapshots
24 since 2007
Dovecot's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store